WordPress Core, Route Confusion and SQL Injection, CVE-2026-63030 (Critical) -DC-Oct2026-3015

Listen to this Post

CVE-2026-63030 represents a critical security vulnerability affecting WordPress Core.
The flaw resides specifically within the REST API batch processor endpoint.
Unauthenticated remote attackers can exploit this logic flaw easily.
It enables attackers to bypass standard permission checks entirely.
The vulnerability stems from a desynchronization in request handling.
Validation loops and execution loops fail to align properly.

When `wp_parse_url()` encounters malformed sub-request paths, errors occur.

These errors are added to validation arrays but omitted from matches.
As a result, subsequent sub-requests dispatch to incorrect internal routes.

An attacker wraps nested requests targeting sensitive endpoints.

This route confusion chains directly with an SQL injection flaw.
The secondary flaw is tracked as CVE-2026-60137 in WP_Query.

Specifically, the `author__not_in` parameter lacks proper input sanitization.

When passed as a scalar string, it interpolates into raw SQL.

Attackers inject malicious payloads containing conditional timing functions.

This creates a robust timing oracle against the backend database.
Attackers extract database contents, user credentials, and password hashes.
Further escalation leverages object poisoning and recursive batch calls.
Forced customizer changesets trick WordPress into granting admin rights.
Once an administrator account is forged, malicious plugins upload.
These plugins deploy web shells for full remote code execution.
CISA has added this critical vulnerability to the KEV catalog.
Active exploitation in the wild has been widely documented.

Immediate patching and endpoint restriction are strongly advised.

The flaw impacts default installations without requiring extra plugins.
Automated scanners on the internet detect vulnerable instances instantly.
System administrators must verify installed versions across all servers.

Network firewalls should block suspicious payloads immediately.

Swift remediation prevents total infrastructure compromise.

DailyCVE Form:

Platform: WordPress Core
Version: 6.9.x, 7.0.x
Vulnerability: Route Confusion SQLi
Severity: Critical Severity
date: July 2026

Prediction: Patched July 2026

What Undercode Say:

Analysis of the vulnerability reveals deep flaws in REST API batch handling.
The separation of validation and execution loops creates desynchronization.

Attackers manipulate sub-request routing to bypass authorization boundaries.

The combination with CVE-2026-60137 turns logic bugs into database compromise.
Query parameters fail to sanitize scalar string inputs correctly.
Automated scanners and malicious scripts actively probe endpoints globally.
Defenders must analyze access logs for anomalous batch requests.
Monitoring file integrity across core directories detects unauthorized modifications.
Code execution occurs via uploaded plugins containing web shells.
Securing database tables and rotating secrets mitigates persistence risks.

Bash commands and codes:

python3 wp2shell.py --target https://example.com --check
python3 wp2shell.py --target https://example.com --exploit --user admin
curl -X POST "https://example.com/wp-json/batch/v1" -H "Content-Type: application/json" -d '{"requests":[{"path":"/wp/v2/categories?author__not_in=1"}]}'

Exploit: (Educational Purposes!)

The exploit begins by sending a crafted JSON payload to /wp-json/batch/v1.
The payload includes malformed sub-requests designed to trigger route confusion.

By desynchronizing validation arrays, restricted routes become accessible.

The nested request targets category endpoints containing the vulnerable parameter.

The `author__not_in` parameter receives malicious SQL injection syntax.

Using time-based blind SQL injection, data is extracted character by character.
Next, recursive batch requests force a customizer changeset action.
This action temporarily grants administrative privileges to a forged session.
The attacker utilizes this brief window to upload a malicious PHP plugin.
Activating the plugin executes arbitrary commands on the underlying server.

Protection: from this CVE

Upgrade immediately to WordPress version 6.9.5 or 7.0.2.

Apply web application firewall rules to block access to /wp-json/batch/v1.

Restrict unauthenticated REST API access using security plugins.

Monitor server logs for unexpected administrative account creation.

Implement file integrity monitoring on `wp-content/` and core directories.
Rotate all administrator passwords and authentication keys in wp-config.php.

Impact:

Complete compromise of the underlying web server and database.

Unauthenticated remote code execution with elevated privileges.

Data theft including user credentials, sensitive posts, and customer data.

Potential website defacement and malware distribution to visitors.

Persistence via planted web shells and unauthorized administrator accounts.
Rozhanitsy Mythology Overview
This video provides background on the cultural origins of the name Rozhanitsy referenced in the software tooling.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top